Assurly
Claude connectorCommunityPre-launch security scan for any live web app. Finds leaked API keys, an exposed Supabase database and missing security headers, with a shi…
- Tools
- 1
exposed by this connector
Movement
From our daily snapshots over the last 30 days.
Rank by popularity
Not enough data points to chart.
Rank by trending score
Popularity score
Not enough data points to chart.
Trending score
In its category
How this connector compares with others in the same category. Positions are counted within the category, not across the whole directory.
Developer tools479th of 560 by popularity · not ranked by trending score
This connector isn’t ranked by trending score, so the category’s top connectors are shown instead.
| # | Connector | Trending | Popularity | 7d |
|---|---|---|---|---|
| 1 | 295,964 | — | ||
| 2 | 265,438 | 56places up | ||
| 3 | 183,079 | 18places up | ||
| 4 | 167,886 | 140places up | ||
| 5 | 165,814 | 44places up | ||
| 6 | 149,997 | 43places up | ||
| 7 | 147,888 | — |
Find the security holes in your live app before strangers do.
Ask Claude "Is my app safe to launch?" with your URL, and Assurly scans the deployed app from the outside, the way anyone on the internet sees it. It is built for apps made with AI builders and coding agents such as Lovable, Bolt, v0, Replit and Cursor, where secret keys and database access often end up in public code.
What Assurly finds
- Leaked secret keys in your page or JavaScript bundle: Stripe secret keys, AWS access keys, Google API keys and Supabase service-role keys
- An exposed Supabase database: your public key reaches it straight from the browser, the setup where a single table without row-level security (RLS) leaks user data
- Missing security headers: Content-Security-Policy, Strict-Transport-Security and X-Content-Type-Options
- A dead or broken deployment that should not get a green light
What you get
- A ship verdict: Ready to ship, Review recommended or Not ready to ship
- A Ship Score from 0 to 100
- For every problem, what it means for your users and a concrete fix, including the exact headers to add on Vercel
Try asking
- "Is my Lovable app safe to launch? my-app.lovable.app"
- "Scan my site for leaked API keys before I go live"
- "I rotated the key and redeployed. Check again."
Safe by design The scan is passive and needs no signup. Assurly loads your public page and scripts like a browser does; it never logs in, submits forms or reads your data. When a firewall or deployment protection keeps it from seeing the app, it says so instead of guessing. To prove whether your Supabase tables are actually readable, verify ownership at assurly.dev and run the full active test there.
Tools
- check_live_app
- Categories
- Sign-in
- Not required
- Connector URL
- https://assurly.dev/api/mcp
- Transport
- Streamable HTTP
- Works with
- Claude, Claude API, Claude Code, Claude Desktop
- Added
- September 26, 2026
- More info